Vulnerabilities (CVE)

Filtered by vendor Labsmedia Subscribe
Filtered by product Clickheat
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-4659 1 Labsmedia 1 Clickheat 2023-12-10 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a config action to index.php.